CVE-2023-24035
Received Received - Intake

Timing Attack in Nagios XI Authentication

Vulnerability report for CVE-2023-24035, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: MITRE

Description

An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing comparison that leads to an attacker being able to bruteforce the admin password, by measuring timing differences in the comparison.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nagios nagios_xi to 5.9.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-208 Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Nagios XI versions before 5.9.3. It involves a timing attack due to an insecure comparison in the is_insecure_login_authenticated function. An attacker can exploit this by measuring timing differences during password authentication to brute force the admin password.

Impact Analysis

An attacker could gain unauthorized access to the Nagios XI admin account by brute forcing the password. This could allow them to view sensitive system information, modify configurations, or disrupt services.

Mitigation Strategies

Upgrade Nagios XI to version 5.9.3 or later to address the insecure timing comparison vulnerability in the admin password authentication process.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-24035. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart